CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Supply Chain Attacks Surge in March 2026

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6256

As cited

Copy frozen at (site build).

threat intel

Supply Chain Attacks Surge in March 2026

In March 2026, multiple high-impact open-source packages were compromised in supply chain attacks. The Axios NPM package (versions 1.14.1 and 0.30.4) was taken over via a maintainer account compromise and injected with a cross-platform remote access trojan (RAT) dropper. A threat group called TeamPCP also poisoned LiteLLM versions 1.82.7 and 1.82.8 on PyPI to harvest cloud credentials, SSH keys, and Kubernetes tokens for lateral movement in CI/CD and production environments.

Why it matters: Developers and DevOps teams using Axios or LiteLLM must immediately check for and remove compromised versions from package-lock.json, yarn.lock, and PyPI environments, revoke exposed credentials, and scan systems for connections to identified command-and-control domains; organizations must also strengthen supply chain defenses with Software Composition Analysis (SCA) tools, multifactor authentication (MFA), and restricted package manager access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Supply Chain Attacks Surge in March 2026

In March 2026, multiple high-impact open-source packages were compromised in supply chain attacks. The Axios NPM package (versions 1.14.1 and 0.30.4) was taken over via a maintainer account compromise and injected with a cross-platform remote access trojan (RAT) dropper. A threat group called TeamPCP also poisoned LiteLLM versions 1.82.7 and 1.82.8 on PyPI to harvest cloud credentials, SSH keys, and Kubernetes tokens for lateral movement in CI/CD and production environments.

Why it matters: Developers and DevOps teams using Axios or LiteLLM must immediately check for and remove compromised versions from package-lock.json, yarn.lock, and PyPI environments, revoke exposed credentials, and scan systems for connections to identified command-and-control domains; organizations must also strengthen supply chain defenses with Software Composition Analysis (SCA) tools, multifactor authentication (MFA), and restricted package manager access.

VendorsAmazon Web ServicesAppleGitHubGoogleKubernetesMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary